CVEFeed Newsroom – Latest Cybersecurity Updates

The "Cyber Newsroom Feed" module is a live feed of the latest cyber news enriched with CVE and vulnerability data. The feed is updated every 5 minutes and includes the latest news from the cyber security industry. The feed is designed to provide users with a comprehensive overview of the latest cyber security news and trends.

  • The Hacker News
Bing Images Flaws Let Crafted SVGs Run Commands as SYSTEM on Microsoft's Servers

A crafted SVG submitted to Bing's image search ran commands as NT AUTHORITY\SYSTEM on Microsoft's production image-processing workers, and as root on the Linux machines in the same fleet. XBOW's testi ...

Published Date: Jul 24, 2026 (4 days, 8 hours ago)
  • cert.pl
Vulnerability in Apereo CAS Client software

Vulnerability in Apereo CAS Client software CVE ID CVE-2026-15243 Publication date 24 July 2026 Vendor Apereo Product Java Apereo CAS ClientJasig CAS Client Vulnerable versions 4.1.0 Java Apereo CAS C ...

Published Date: Jul 24, 2026 (4 days, 9 hours ago)
  • The Hacker News
Hacker Runs Hermes AI Agent Unattended for Post-Exploitation at Thai Finance Ministry

Someone installed a popular AI assistant on a rented server, switched off the setting that makes it ask permission before running risky commands, and pointed it at Thailand's Ministry of Finance, whic ...

Published Date: Jul 24, 2026 (4 days, 10 hours ago)
  • cert.pl
Vulnerabilities in GNU coreutils software

Vulnerabilities in GNU coreutils software CVE ID CVE-2026-56391 Publication date 24 July 2026 Vendor GNU Product coreutils Vulnerable versions From 9.5 through 9.11 Vulnerability type (CWE) Out-of-bou ...

Published Date: Jul 24, 2026 (4 days, 11 hours ago)
  • The Hacker News
NodeBB Patches Eight AI-Found Flaws Exposing Admin Access and Private Chats

Eight security flaws in NodeBB went public on Wednesday, along with the code to exploit them. Aikido Security rates all eight as high severity and says its AI pentest agents found them in a six-hour r ...

Published Date: Jul 24, 2026 (4 days, 12 hours ago)
  • The Hacker News
Kimi K3 Agents Found Redis Zero-Days and Built RCE Exploit, Researchers Say

Redis shipped seven security releases on July 23 after researchers published authenticated RCE PoCs for stock Redis 6.2.22, 7.4.9, 8.6.4, and 8.8.0. All four chains require RESTORE. The Streams chains ...

Published Date: Jul 24, 2026 (4 days, 13 hours ago)
  • The Hacker News
Fake Notepad++ Plugin Delivers MATCHBOIL.V2 in UAC-0099 Attacks

The Computer Emergency Response Team of Ukraine (CERT-UA) has warned of a new campaign that involves the use of a malicious program that's dressed up as a Notepad++ plugin to compromise Windows system ...

Published Date: Jul 24, 2026 (4 days, 13 hours ago)
  • The Cyber Express
Russian-Linked Hackers Target Zimbra Users With Zero-Day Exploit

A Zimbra phishing campaign attributed to Russian state-supported cyber actors has targeted Western government and commercial organizations, exploiting CVE-2025-66376 to access sensitive email data and ...

Published Date: Jul 24, 2026 (4 days, 14 hours ago)
  • Trend Micro
The Signs Were There: What the First Autonomous Ransomware Case Confirms

Cyber Threats An AI agent has run a ransomware intrusion on its own for the first time, from break-in to data destruction. The autonomous attacks TrendAI™ Research predicted are beginning to arrive, ...

Published Date: Jul 24, 2026 (4 days, 20 hours ago)
  • The Hacker News
Russian Espionage Group Exploited Zimbra Zero-Day to Steal Mail and 2FA Codes

A Russian state-supported espionage group spent months reading Western mailboxes through a then-unknown flaw in Zimbra's webmail client. The payload goes after the last 90 days of email, the organizat ...

Published Date: Jul 23, 2026 (5 days, 1 hour ago)

Filters

Filter news that are affecting your technology stack
Showing 10 of 11914 Results